IP Library Granted Patent US 10,171,243
Granted Patent B2
US 10,171,243 · App. 15/612,885 · Granted Jan 1, 2019

Self-validating request message structure and operation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,171,243
App. No.
15/612,885
Granted
Jan 1, 2019
Kind
B2
Abstract

A method begins by a first device generating a self-validating message by creating a master key, using the master key to create a message encryption key, encrypting a message using the message encryption key to produce an encrypted message, encrypting the master key using a public key of a second device to produce an encrypted master key, and including a message authentication code of the first device in the self-validating message. The method continues by the second device receiving and decoding the self-validating message by verifying the message authentication code of the first device, and when the message authentication code of the first device is verified, decrypting the encrypted master key using a private key of the second device to recover the master key, using the master key to create the message encryption key, and decrypting the encrypted message using the message encryption key to recover the message.

Claims (55)

1. A storage unit (SU) comprising:

an interface configured to interface and communicate with a dispersed or distributed storage network (DSN);

memory that stores operational instructions; and

a processing module operably coupled to the interface and to the memory, wherein the processing module, when operable within the SU based on the operational instructions, is configured to:

receive, via the DSN and from a computing device, a self-validating request message, wherein the self-validating request message is generated by the computing device to include a first message authentication code of the computing device, and the self-validating request message is generated by the computing device based on the computing device creating a master key of the computing device, creating a message encryption key based on the master key of the computing device and a secret function, encrypting a message using the message encryption key to generate an encrypted message, encrypting the master key of the computing device using a public key of the SU to generate an encrypted master key;

process the self-validating request message to verify the first message authentication code of the computing device that is included within the self-validating request message, and when the first message authentication code of the computing device is verified:

decrypt the encrypted master key that is included within the self-validating request message using a private key of the SU to recover the master key of the computing device;

generate the message encryption key based on the master key of the computing device and the secret function; and

decrypt the encrypted message that is included within the self-validating request message to recover the message; and

generate, in response to the self-validating request message, a self-validating response message that includes a second message authentication code and an encrypted response including to:

generate a responder encryption key based on the master key and another secret function; and

encrypt a response to the message based on the responder encryption key to generate the encrypted response; and

transmit, via the DSN and to the computing device, the self-validating response message.

2. The SU of claim 1 , wherein the self-validating request message includes a self-validating request header, the first message authentication code of the computing device, and an encrypted request that is generated by using a requester encryption key to process a request message that corresponds to a write request, a delete request, a list request, or a read request.

3. The SU of claim 2 , wherein request message corresponds to the write request, the delete request, the list request, or the read request to be applied to at least one encoded data slice (EDS) stored within the SU, wherein a data object is segmented into a plurality of data segments, wherein a data segment of the plurality of data segments is dispersed error encoded in accordance with dispersed error encoding parameters to produce a set of encoded data slices (EDSs) that includes the at least one EDS, and wherein the set of EDSs are distributedly stored among a plurality of storage units (SUs) that includes the SU.

4. The SU of claim 2 , wherein the self-validating request header includes a timestamp, a universally unique identifier (UUID) associated with the self-validating request message, the encrypted master key, a certificate chain of the computing device, and a header signature.

5. The SU of claim 4 , wherein the certificate chain of the computing device is generated by the computing device when generating the self-validating request header using another private key of a public/private key pair associated with the computing device that includes another private key of the computing device and a another public key of the computing device, and wherein the certificate chain of the computing device includes one or more certificates chained to a certificate authority of the DSN.

6. The SU of claim 1 , wherein the SU is located at a first location that is remotely located from another SU that is located at a second location within the DSN.

7. The SU of claim 1 , wherein the computing device includes a social networking device, a gaming device, a cell phone, a smart phone, a personal digital assistant, a digital music player, a digital video player, a laptop computer, a handheld computer, a tablet, or a video game controller.

8. The SU of claim 1 , wherein the DSN includes at least one of a wireless communication system, a wire lined communication system, a private intranet system, a public internet system, a local area network (LAN), or a wide area network (WAN).

9. A storage unit (SU) comprising:

an interface configured to interface and communicate with a dispersed or distributed storage network (DSN);

memory that stores operational instructions; and

a processing module operably coupled to the interface and to the memory, wherein the processing module, when operable within the SU based on the operational instructions, is configured to:

receive, via the DSN and from a computing device, a self-validating request message that is generated by the computing device and that includes a self-validating request header and a first message authentication code of the computing device, wherein the self-validating request header includes a timestamp, a universally unique identifier (UUID) associated with the self-validating request message, an encrypted master key, a certificate chain of the computing device, and a header signature, and wherein the self-validating request message is generated by the computing device based on the computing device creating a master key of the computing device, creating a message encryption key based on the master key of the computing device and a secret function, encrypting a message using the message encryption key to generate an encrypted message, encrypting the master key of the computing device using a public key of the SU to generate the encrypted master key;

process the self-validating request message to verify the first message authentication code of the computing device that is included within the self-validating request message, and when the first message authentication code of the computing device is verified:

decrypt the encrypted master key that is included within the self-validating request message using a private key of the SU to recover the master key of the computing device;

generate the message encryption key based on the master key of the computing device and the secret function; and

decrypt the encrypted message that is included within the self-validating request message to recover the message; and

generate, in response to the self-validating request message, a self-validating response message that includes a second message authentication code and an encrypted response including to:

generate a responder encryption key based on the master key and another secret function; and

encrypt a response to the message based on the responder encryption key to generate the encrypted response; and

transmit, via the DSN and to the computing device, the self-validating response message.

10. The SU of claim 9 , wherein the self-validating request message also includes an encrypted request that is generated by using a requester encryption key to process a request message that corresponds to a write request, a delete request, a list request, or a read request.

11. The SU of claim 10 , wherein request message corresponds to the write request, the delete request, the list request, or the read request to be applied to at least one encoded data slice (EDS) stored within the SU, wherein a data object is segmented into a plurality of data segments, wherein a data segment of the plurality of data segments is dispersed error encoded in accordance with dispersed error encoding parameters to produce a set of encoded data slices (EDSs) that includes the at least one EDS, and wherein the set of EDSs are distributedly stored among a plurality of storage units (SUs) that includes the SU.

12. The SU of claim 9 , wherein the certificate chain of the computing device is generated by the computing device when generating the self-validating request header using another private key of a public/private key pair associated with the computing device that includes another private key of the computing device and another public key of the computing device, and wherein the certificate chain of the computing device includes one or more certificates chained to a certificate authority of the DSN.

13. The SU of claim 9 , wherein the DSN includes at least one of a wireless communication system, a wire lined communication system, a private intranet system, a public internet system, a local area network (LAN), or a wide area network (WAN).

14. A method for execution by a storage unit (SU), the method comprising:

receiving, via an interface of the SU configured to interface and communicate with a dispersed or distributed storage network (DSN) and from a computing device, a self-validating request message, wherein the self-validating request message is generated by the computing device to include a first message authentication code of the computing device, and the self-validating request message is generated by the computing device based on the computing device creating a master key of the computing device, creating a message encryption key based on the master key of the computing device and a secret function, encrypting a message using the message encryption key to generate an encrypted message, encrypting the master key of the computing device using a public key of the SU to generate an encrypted master key;

processing the self-validating request message to verify the first message authentication code of the computing device that is included within the self-validating request message, and when the first message authentication code of the computing device is verified:

decrypting the encrypted master key that is included within the self-validating request message using a private key of the SU to recover the master key of the computing device;

generating the message encryption key based on the master key of the computing device and the secret function; and

decrypting the encrypted message that is included within the self-validating request message to recover the message; and

generating, in response to the self-validating request message, a self-validating response message that includes a second message authentication code and an encrypted response including to:

generating a responder encryption key based on the master key and another secret function; and

encrypting a response to the message based on the responder encryption key to generate the encrypted response; and

transmitting, via the interface of the SU and to the computing device, the self-validating response message.

15. The method of claim 14 , wherein the self-validating request message includes a self-validating request header, the first message authentication code of the computing device, and an encrypted request that is generated by using a requester encryption key to process a request message that corresponds to a write request, a delete request, a list request, or a read request.

16. The method of claim 15 , wherein request message corresponds to the write request, the delete request, the list request, or the read request to be applied to at least one encoded data slice (EDS) stored within the SU, wherein a data object is segmented into a plurality of data segments, wherein a data segment of the plurality of data segments is dispersed error encoded in accordance with dispersed error encoding parameters to produce a set of encoded data slices (EDSs) that includes the at least one EDS, and wherein the set of EDSs are distributedly stored among a plurality of storage units (SUs) that includes the SU.

17. The method of claim 15 , wherein the self-validating request header includes a timestamp, a universally unique identifier (UUID) associated with the self-validating request message, the encrypted master key, a certificate chain of the computing device, and a header signature.

18. The method of claim 17 , wherein the certificate chain of the computing device is generated by the computing device when generating the self-validating request header using another private key of a public/private key pair associated with the computing device that includes another private key of the computing device and another public key of the computing device, and wherein the certificate chain of the computing device includes one or more certificates chained to a certificate authority of the DSN.

19. The method of claim 14 , wherein at least one of:

the SU is located at a first location that is remotely located from another SU that is located at a second location within the DSN; or

the computing device includes a social networking device, a gaming device, a cell phone, a smart phone, a personal digital assistant, a digital music player, a digital video player, a laptop computer, a handheld computer, a tablet, or a video game controller.

20. The method of claim 14 , wherein the DSN includes at least one of a wireless communication system, a wire lined communication system, a private intranet system, a public internet system, a local area network (LAN), or a wide area network (WAN).

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2017
From: LEGGETTE, WESLEY; RESCH, JASON K.
To: CLEVERSAFE, INC.
Reel/Frame 042579/0523 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2017
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 042671/0120 →